Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9m7h-2ggv-4q9j

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.

IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.

EPSS

Процентиль: 18%
0.00059
Низкий

Связанные уязвимости

nvd
около 20 лет назад

IPCop (aka IPCop Firewall) before 1.4.10 has world-readable permissions for the backup.key file, which might allow local users to overwrite system configuration files and gain privileges by creating a malicious encrypted backup archive owned by "nobody", then executing ipcoprscfg to restore from this backup.

EPSS

Процентиль: 18%
0.00059
Низкий